CISS 320 Chapter 9

10 September 2022
4.7 (114 reviews)
15 test answers

Unlock all answers in this set

Unlock answers (11)
question
What is considered the 'cleanup rule' on a Cisco router?
answer
implicit deny all
question
What service uses UDP port 53?
answer
DNS
question
What should a company concerned about protecting its data warehouses and employee privacy might consider installing on the network perimeter to prevent direct connections between the internal network and the Internet?
answer
proxy server
question
What type of attack are stateless packet filters particularly vulnerable to?
answer
IP spoofing attacks
question
What type of ICMP packet can an attacker use to send traffic to a computer they control outside the protected network?
answer
Redirect
question
Which element of a rule base conceals internal names and IP addresses from users outside the network?
answer
NAT
question
Which of the following is a general practice for a rule base?
answer
permit access to public servers in the DMZ
question
Which of the following is a method for supporting IPv6 on IPv4 networks until IPv6 is universally adopted?
answer
Teredo tunneling
question
Which of the following is an advantage of hardware firewalls?
answer
not dependent on a conventional OS
question
Which of the following is a typical drawback of a free firewall program?
answer
cannot monitor traffic in real time
question
Which of the following is described as the combination of an IP address and a port number?
answer
socket
question
Which of the following is NOT a criteria typically used by stateless packet filters to determine whether or not to block packets.
answer
data patterns
question
Which of the following is NOT among the common guidelines that should be reflected in the rule base to implement an organization's security policy?
answer
employees can use instant-messaging only with external network users
question
Which of the following is NOT an ICMPv6 packet type that you should allow within your organization but never outside the organization?
answer
Packet Redirect
question
Which of the following is NOT a protocol,port pair that should be filtered when an attempt is made to make a connection from outside the company network?
answer
TCP,80